This Data Processing Addendum ("DPA") forms part of and supplements the Terms of Use, Vendor Agreement, Subscription Agreement, or any other agreement (collectively, the "Agreement") entered into between Baycarl LLC, operating VendPost ("VendPost," "Processor," "Service Provider," "we," "us," or "our"), and the business, vendor, organization, or customer using the Services ("Controller," "Customer," or "you").
This DPA applies whenever VendPost processes Personal Data on behalf of a Customer in connection with the Services and is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, applicable U.S. privacy laws including the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection laws.
1. Definitions
For purposes of this DPA:
- "Controller": Means the natural or legal person that determines the purposes and means of processing Personal Data.
- "Processor": Means the entity that processes Personal Data on behalf of the Controller.
- "Personal Data": Means any information relating to an identified or identifiable natural person as defined under applicable Data Protection Laws.
- "Processing": Means any operation performed on Personal Data including collection, storage, organization, use, disclosure, transmission, retrieval, deletion, or destruction.
- "Data Subject": Means an identified or identifiable individual whose Personal Data is processed.
- "Sub-Processor": Means a third party engaged by VendPost to process Personal Data on behalf of the Customer.
- "Data Protection Laws": Means all applicable privacy and data protection laws including GDPR, UK GDPR, CCPA/CPRA, and other applicable privacy regulations.
- "Personal Data Breach": Means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
2. Scope of Processing
VendPost may process Personal Data solely for the purpose of providing the Services described in the Agreement. Processing activities may include:
- Hosting vendor and customer accounts;
- Displaying business listings;
- Managing profiles;
- Providing messaging functionality;
- Supporting community features;
- Managing customer support requests;
- Operating analytics systems;
- Maintaining platform security;
- Preventing fraud and abuse;
- Performing backup and recovery operations.
VendPost shall process Personal Data only in accordance with documented instructions from the Customer unless required otherwise by applicable law.
3. Categories of Personal Data
Depending on how the Services are used, VendPost may process:
- User Identification Information: Full names, Usernames, Business names, Email addresses, Telephone numbers
- Business Information: Business descriptions, Service offerings, Certifications, Licenses, Portfolio information
- Technical Information: IP addresses, Device identifiers, Browser information, Usage logs, Login records
- Communications Data: Messages, Support tickets, Community posts, Comments, User interactions
- Customer Relationship Information: Booking requests, Service inquiries, Transaction-related communications
VendPost does not intentionally process special categories of personal data unless expressly submitted by users.
4. Categories of Data Subjects
Personal Data processed under this DPA may relate to:
- Vendors, Service providers, Business owners, Clients, Customers
- Community members, Website visitors
- Authorized representatives of customers
- Customer employees and contractors
5. Processor Obligations
- Process Only on Instructions: Process Personal Data solely in accordance with documented instructions from the Controller unless otherwise required by law.
- Maintain Confidentiality: Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
- Limit Access: Restrict access to Personal Data to personnel with a legitimate business need to access such information.
- Implement Security Measures: Maintain reasonable technical and organizational safeguards designed to protect Personal Data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
- Notify of Legal Restrictions: Inform the Customer if VendPost believes any processing instruction violates applicable Data Protection Laws.
6. Customer Obligations
The Customer represents and warrants that:
- It has obtained all necessary rights and permissions to provide Personal Data to VendPost;
- It has provided required privacy notices;
- It has obtained valid consent where required;
- Its instructions comply with applicable laws;
- It remains responsible for determining the lawful basis for processing.
The Customer remains the Controller of Personal Data and retains responsibility for compliance with applicable Data Protection Laws.
7. Sub-Processors
The Customer authorizes VendPost to engage Sub-Processors necessary to provide the Services. Examples may include Cloud hosting providers, Infrastructure providers, Analytics providers, Email service providers, Security monitoring providers, and Customer support platforms.
VendPost shall:
- Enter into appropriate agreements with Sub-Processors;
- Require Sub-Processors to maintain adequate data protection measures;
- Remain responsible for the performance of its Sub-Processors regarding Personal Data processing obligations.
Customers may request information regarding current Sub-Processors by contacting VendPost.
8. Security Measures
VendPost shall maintain appropriate technical and organizational measures designed to protect Personal Data. Such measures may include:
- Technical Measures: Encryption in transit using TLS, Encrypted storage where appropriate, Authentication controls, Access management systems, Logging and monitoring, Malware protection, Network security controls, Backup systems
- Organizational Measures: Access control policies, Confidentiality obligations, Security awareness training, Incident response procedures, Vendor management processes, Risk assessments
Security measures may evolve as technologies and risks change.
9. Personal Data Breach Notification
If VendPost becomes aware of a Personal Data Breach affecting Customer Personal Data, VendPost shall:
- Notify the Customer without undue delay;
- Provide available information regarding the incident;
- Take reasonable steps to investigate and mitigate the incident;
- Cooperate with the Customer regarding breach response obligations.
Notification of a security incident does not constitute an admission of fault or liability.
10. Assistance with Data Subject Requests
Where legally required and reasonably feasible, VendPost shall assist the Customer in responding to requests involving: Access requests, Correction requests, Deletion requests, Data portability requests, Restriction requests, Objection requests, and Consent withdrawal requests.
The Customer remains responsible for responding to Data Subject requests.
11. Data Protection Impact Assessments
To the extent required by law and reasonably requested, VendPost shall provide information reasonably necessary to assist the Customer with Data Protection Impact Assessments (DPIAs), Regulatory consultations, and Privacy risk assessments. Such assistance may be subject to reasonable limitations and reimbursement of costs where permitted by law.
12. International Data Transfers
VendPost may process Personal Data in the United States and other jurisdictions where VendPost or its service providers operate.
Where required by law, international transfers shall be protected through appropriate transfer mechanisms, including European Commission Standard Contractual Clauses (SCCs), UK International Data Transfer Addendum, or other legally recognized transfer safeguards.
Where applicable, the parties agree that the current European Commission Standard Contractual Clauses are incorporated into this DPA by reference.
13. Data Retention, Return & Deletion
Upon termination of the Agreement, and subject to legal obligations requiring retention, VendPost shall return Customer Personal Data where reasonably feasible; or securely delete Customer Personal Data.
VendPost may retain information where necessary to comply with legal obligations, resolve disputes, enforce agreements, maintain security records, or prevent fraud. Backup copies may remain until overwritten through standard retention schedules.
14. Audit Rights
Upon reasonable written notice and no more than once annually, the Customer may request information reasonably necessary to verify VendPost's compliance with this DPA.
VendPost may satisfy such requests by providing security documentation, compliance certifications, audit summaries, or responding to security questionnaires.
Audits must not unreasonably interfere with business operations or compromise security.
15. California Privacy Law Compliance
To the extent CCPA/CPRA applies:
- VendPost acts as a Service Provider or Contractor.
- VendPost shall not sell Personal Information received from Customers.
- VendPost shall not retain, use, or disclose Personal Information except as permitted by applicable law and the Agreement.
- VendPost shall implement reasonable safeguards to protect Personal Information.
16. Liability
Except as expressly provided in this DPA, liability shall be governed by the limitation of liability provisions contained in the Agreement and Terms of Use. Nothing in this DPA expands the liability of either party beyond the limitations agreed elsewhere in the governing Agreement.
17. Order of Precedence
In the event of any conflict between Applicable Data Protection Laws, Standard Contractual Clauses, This DPA, and The Agreement, the documents shall govern in that order with respect to data protection matters.
18. Contact Information
For privacy, security, or data protection inquiries, contact:
Annex I – Processing Details
- Subject Matter: Provision of VendPost marketplace, community, messaging, and vendor-discovery services.
- Nature of Processing: Collection, storage, organization, display, transmission, moderation, and deletion of Personal Data.
- Purpose of Processing: To provide, secure, maintain, and improve the Services.
- Duration: For the duration of the Agreement and as otherwise permitted by applicable law.
- Categories of Data Subjects: Vendors, Clients, Community members, Visitors, Customer personnel.
- Categories of Personal Data: Identification data, Contact information, Business information, Communications data, Technical and usage information.
Annex II – Technical & Organizational Measures
VendPost maintains reasonable safeguards including:
- TLS encryption in transit
- Access controls and role-based permissions
- Logging and monitoring
- Secure authentication
- Security incident procedures
- Backup and recovery systems
- Vendor risk management controls
Annex III – Current Sub-Processor Categories
VendPost may use: Cloud hosting providers, Database providers, Analytics providers, Email delivery providers, Customer support platforms, Security monitoring services. A current list may be provided upon request.